PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39501 RealMag777 CVE debrief

A Missing Authorization vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FOX: from n/a through <= 1.4.5. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users of RealMag777 FOX woocommerce-currency-switcher plugin for WordPress should verify their installation and update to a patched version if necessary. The CVE record was published on 2026-04-08T09:16:24.373Z and last modified on 2026-07-24T21:10:00.143Z.

Vendor
RealMag777
Product
FOX
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Users of RealMag777 FOX woocommerce-currency-switcher plugin for WordPress, security teams, and operators should verify their installation and update to a patched version if necessary. This vulnerability affects WordPress deployments using the FOX plugin, specifically version 1.4.5 and earlier.

Technical summary

The CVE-2026-39501 vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. It was published on 2026-04-08T09:16:24.373Z and last modified on 2026-07-24T21:10:00.143Z. The vulnerability is related to missing authorization in the RealMag777 FOX woocommerce-currency-switcher plugin. Affected users should verify their installation and update to a patched version if necessary.

Defensive priority

Medium priority due to the vulnerability's MEDIUM severity and potential impact on access control.

Recommended defensive actions

  • Verify the version of RealMag777 FOX woocommerce-currency-switcher plugin and update to a patched version if necessary.
  • Implement compensating controls to monitor and restrict access to sensitive areas of the plugin.
  • Review and adjust access control configurations to prevent exploitation of incorrectly configured security levels.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Evidence notes

The CVE record was published on 2026-04-08T09:16:24.373Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Deferred. The vulnerability affects FOX plugin for WordPress, specifically version 1.4.5 and earlier. Users should verify their installation and update to a patched version if necessary. Evidence of exploitation is limited, and defenders should verify the affected scope and severity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:24.373Z and has not been modified since then. The NVD entry is currently Deferred.